main change is to force spring security to always send user to welcome.mvc after login which gets their session setup properly before redirecting to start.mvc